Hypersparse Network Flow Analysis of Packets with GraphBLAS
Tyler Trigg, Chad Meiners, Sandeep Pisharody, Hayden Jananthan,, Michael Jones, Adam Michaleas, Timothy Davis, Erik Welch, William Arcand,, David Bestor, William Bergeron, Chansup Byun, Vijay Gadepally, Micheal Houle,, Matthew Hubbell, Anna Klein, Peter Michaleas

TL;DR
This paper introduces a novel GraphBLAS-based hypersparse matrix method for compressing and analyzing large-scale network flow data, enabling efficient temporal aggregation, anomaly detection, and background modeling at unprecedented scale.
Contribution
It presents a new hypersparse matrix compression and resampling technique using GraphBLAS that preserves privacy and allows detailed temporal analysis of network flows.
Findings
Achieved compression below 0.1 bits per packet.
Performed analysis on over a million packets per second.
Scalability demonstrated on the MIT SuperCloud with hundreds of sites.
Abstract
Internet analysis is a major challenge due to the volume and rate of network traffic. In lieu of analyzing traffic as raw packets, network analysts often rely on compressed network flows (netflows) that contain the start time, stop time, source, destination, and number of packets in each direction. However, many traffic analyses benefit from temporal aggregation of multiple simultaneous netflows, which can be computationally challenging. To alleviate this concern, a novel netflow compression and resampling method has been developed leveraging GraphBLAS hyperspace traffic matrices that preserve anonymization while enabling subrange analysis. Standard multitemporal spatial analyses are then performed on each subrange to generate detailed statistical aggregates of the source packets, source fan-out, unique links, destination fan-in, and destination packets of each subrange which can then…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsComplex Network Analysis Techniques · Internet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection
